MEDIUM · 4.3

CVE-2024-4220

Prior to 23.1, an information disclosure vulnerability exists within BeyondInsight which can allow an attacker to enumerate usernames.

Vulnerability Description

Prior to 23.1, an information disclosure vulnerability exists within BeyondInsight which can allow an attacker to enumerate usernames.

CVSS Score

4.3

MEDIUM

CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L
Attack Vector
ADJACENT_NETWORK
Attack Complexity
LOW
Privileges Required
HIGH
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
LOW
Integrity
LOW
Availability
LOW

Affected Products

VendorProductVersions
BeyondtrustBeyondinsight< 23.1

Related Weaknesses (CWE)

References

FAQ

What is CVE-2024-4220?

CVE-2024-4220 is a vulnerability with a CVSS score of 4.3 (MEDIUM). Prior to 23.1, an information disclosure vulnerability exists within BeyondInsight which can allow an attacker to enumerate usernames.

How severe is CVE-2024-4220?

CVE-2024-4220 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2024-4220?

Check the references section above for vendor advisories and patch information. Affected products include: Beyondtrust Beyondinsight.